🏥 HIPAA Security Rule • 45 CFR Part 164 Subpart C

Know where your HIPAA readiness stands.

Start a source-backed readiness intake for the current HIPAA Security Rule, covering 45 CFR §§164.302–164.318. Use categories only — never submit PHI.

45 CFR
Current rule scope
5
Categorical inputs
No PHI
Required
$199
Readiness Pack
Start your free HIPAA Security Rule readiness intake
Tell ComplianceStack which organization and ePHI scope categories fit your situation.
No spam. No sales calls. Categorical intake only.
Do not submit PHI. Use categories only. Never enter patient names, medical records, account numbers, credentials, or other patient-level information.
The current HIPAA Security Rule is the starting point. This ComplianceStack intake frames readiness against 45 CFR Part 164 Subpart C, including §§164.302–164.318. It helps establish the right scope for a later gaps, evidence, and reporting workflow without collecting patient-level data or treating a short intake as a formal risk analysis.

HIPAA readiness workflow

A compact path from categorical analysis to prioritized findings and evidence-ready remediation guidance.

1

Initial categorical analysis

Start with role, organization, size, and ePHI-scope categories against the current 45 CFR Part 164 Subpart C. The intake collects no PHI and is directional guidance, not a formal risk analysis.

2

Prioritized findings

Review a directional nine-finding summary across administrative, physical, and technical safeguards, with Critical, High, and Medium priorities, 45 CFR citations, and practical remediation actions.

3

Evidence-ready remediation

Map each gap to representative evidence artifacts and next-step guidance. The $199 HIPAA Evidence-Ready Readiness Pack provides the gated PDF deliverable—not a formal attestation or organization-specific audit.

Free readiness analysis vs. HIPAA Readiness Pack

Start with categorical scope guidance, then choose the paid educational deliverable when you want a structured, source-backed readiness pack.

Free

Readiness analysis

The current intake is a directional first pass, not an organization-specific finding set.

  • Captures categorical role, organization type and size, and ePHI-scope inputs.
  • Frames the first pass against the current HIPAA Security Rule in 45 CFR Part 164 Subpart C, including §§164.302–164.318.
  • Provides directional readiness and gaps guidance, collects no PHI, and does not replace the organization-specific risk analysis required by 45 CFR §164.308(a)(1)(ii)(A).

What the Intake Covers

The first pass is intentionally limited to non-PHI categories that shape the readiness path.

Organization context

Covered entity, business associate, clearinghouse, hybrid entity, or a healthcare service provider that is still mapping its HIPAA role.

ePHI environment

Clinical systems, cloud and SaaS services, connected systems, limited environments, or business associate service scope.

Security Rule scope

Current requirements in 45 CFR §§164.302–164.318, with the HHS NPRM kept clearly separate as proposed and not final.

HIPAA Readiness Gaps

A public, directional summary of nine prioritized findings across administrative, physical, and technical safeguards. Use the remediation actions as a starting point, then validate scope and risk through a formal organization-specific analysis.

# Priority Safeguard Finding 45 CFR provision Remediation action Primary source Analyze
1 Critical Administrative No documented enterprise-wide risk analysis identifies ePHI threats, vulnerabilities, likelihood, and potential impact. 45 CFR §164.308(a)(1)(ii)(A) Inventory ePHI systems and flows, document threats and vulnerabilities, rate likelihood and impact, and retain the signed analysis. eCFR §164.308(a)(1)(ii)(A) Analyze my org →
2 High Administrative Risk analysis findings are not converted into a documented risk-management plan with assigned owners and due dates. 45 CFR §164.308(a)(1)(ii)(B) Prioritize treatment decisions from the risk analysis, assign accountable owners, set target dates, and track residual risk to closure. eCFR §164.308(a)(1)(ii)(B) Analyze my org →
3 High Administrative Security incident procedures do not clearly assign detection, response, reporting, and mitigation responsibilities. 45 CFR §164.308(a)(6)(ii) Document an incident workflow with escalation contacts, triage criteria, containment steps, reporting decisions, and post-incident mitigation. eCFR §164.308(a)(6)(ii) Analyze my org →
4 Critical Physical Facility access controls do not consistently limit and validate physical access to systems and facilities that house ePHI. 45 CFR §164.310(a)(2)(iii) Maintain a facility access procedure covering authorization, badge or key review, visitor handling, and periodic validation of physical access. eCFR §164.310(a)(2)(iii) Analyze my org →
5 Medium Physical Workstation-use requirements do not define permitted functions, physical surroundings, or safeguards for workstations accessing ePHI. 45 CFR §164.310(b) Publish workstation-use rules for approved functions, placement, privacy, locking, and prohibited handling, then train and attest workforce members. eCFR §164.310(b) Analyze my org →
6 High Physical Device and media procedures do not cover receipt, removal, disposal, reuse, or accountability for ePHI-containing media. 45 CFR §164.310(d)(2)(i)–(iv) Track media custody and movement, approve removals, sanitize or destroy media before disposal or reuse, and retain disposal or reuse records. eCFR §164.310(d)(2)(i)–(iv) Analyze my org →
7 Critical Technical Systems do not consistently enforce unique user access, emergency access, automatic logoff, and encryption or decryption controls. 45 CFR §164.312(a)(1), (a)(2)(i)–(iv) Define access roles, issue unique user IDs, document emergency access, configure automatic logoff where appropriate, and manage encryption or decryption controls. eCFR §164.312(a)(1), (a)(2)(i)–(iv) Analyze my org →
8 Medium Technical Electronic systems lack a reviewed audit trail that records and examines activity involving ePHI and system resources. 45 CFR §164.312(b) Enable audit logging for relevant systems, centralize or protect logs, define review cadence and escalation, and retain review evidence. eCFR §164.312(b) Analyze my org →
9 High Technical User authentication and transmission protections are not consistently verified for systems that access or send ePHI. 45 CFR §164.312(d) and (e)(1) Define authentication checks that verify identity and protect ePHI in transit with documented transmission-security controls and exception handling. eCFR §§164.312(d), (e)(1) Analyze my org →

HIPAA Evidence Checklist

This representative checklist offers directional preparation guidance, not an organization-specific audit opinion. Use it to organize evidence for review against your own scope, policies, systems, and risk decisions.

# Artifact Safeguard 45 CFR provision Preparation guidance Official source
1 Documented enterprise-wide ePHI risk analysis Administrative 45 CFR §164.308(a)(1)(ii)(A) Assemble the current system and data-flow inventory, threat and vulnerability analysis, likelihood and impact ratings, methodology, scope, approval date, and retained sign-off. eCFR §164.308(a)(1)(ii)(A)
2 Risk-management plan and treatment tracker Administrative 45 CFR §164.308(a)(1)(ii)(B) Assemble the approved plan tied to risk-analysis findings, with treatment decisions, accountable owners, target dates, residual-risk decisions, status history, and evidence of periodic review. eCFR §164.308(a)(1)(ii)(B)
3 Security incident-response procedure and test record Administrative 45 CFR §164.308(a)(6)(ii) Retain the approved response procedure plus a dated tabletop or other test record showing participants, detection and escalation steps, reporting decisions, lessons learned, and corrective actions. eCFR §164.308(a)(6)(ii)
4 Facility-access authorization and review records Physical 45 CFR §164.310(a)(2)(iii) Assemble the facility-access procedure, authorized-person or badge and key lists, visitor controls, review dates, approver sign-offs, and records showing access was removed or updated when roles changed. eCFR §164.310(a)(2)(iii)
5 Workstation-use policy, training attestations, and inspection records Physical 45 CFR §164.310(b) Retain the approved policy, dated workforce training and attestations, and representative inspection records covering permitted functions, workstation placement, privacy, locking, and prohibited handling. eCFR §164.310(b)
6 Device and media inventory, movement, sanitization, and disposal records Physical 45 CFR §164.310(d)(2)(i)–(iv) Assemble an inventory and custody trail for devices and media, removal approvals, movement logs, sanitization or destruction certificates, disposal records, and reuse decisions with dates and responsible personnel. eCFR §164.310(d)(2)(i)–(iv)
7 Access-control and IAM configuration evidence Technical 45 CFR §164.312(a)(1), (a)(2)(i)–(iv) Capture dated configuration exports or screenshots, role and unique-ID standards, emergency-access procedures, automatic-logoff settings, encryption or decryption controls, and review or approval records. eCFR §164.312(a)(1), (a)(2)(i)–(iv)
8 Audit-log configuration and review records Technical 45 CFR §164.312(b) Retain logging configurations for relevant systems, a protected or centralized log sample, dated review reports, reviewer approvals, escalation records, and the defined retention period. eCFR §164.312(b)
9 Authentication and transmission-security validation record Technical 45 CFR §164.312(d), (e)(1) Assemble dated validation or test results for identity verification and ePHI transmission protections, including protocols, scope, exceptions, remediation owners, approval, and retention of follow-up evidence. eCFR §§164.312(d), (e)(1)

Primary Sources for This Analyzer

Current rule: 45 CFR Part 164 Subpart C, §§164.302–164.318 — official eCFR text. The current Security Rule is the source-of-truth frame for this Slice 1 intake.

Proposed rule — not final: HHS HIPAA Security Rule NPRM. ComplianceStack labels this HHS notice as proposed and does not treat it as an enacted replacement for the current rule.

Illustrative public preview

What the readiness pack can produce

These examples show the shape of the paid readiness experience rather than organization-specific findings or delivered results.

Control finding

No documented enterprise-wide risk analysis identifies ePHI threats, vulnerabilities, likelihood, and potential impact.

Inventory ePHI systems and flows, document threats and vulnerabilities, rate likelihood and impact, and retain the signed analysis.

Critical priority 45 CFR §164.308(a)(1)(ii)(A)
Evidence request

Documented enterprise-wide ePHI risk analysis

Assemble the current system and data-flow inventory, threat and vulnerability analysis, likelihood and impact ratings, methodology, scope, approval date, and retained sign-off.

Critical priority 45 CFR §164.308(a)(1)(ii)(A)
Remediation priority

Risk analysis findings are not converted into a documented risk-management plan with assigned owners and due dates.

Prioritize treatment decisions from the risk analysis, assign accountable owners, set target dates, and track residual risk to closure.

High priority 45 CFR §164.308(a)(1)(ii)(B)

HIPAA Security Rule Readiness FAQ

What does ComplianceStack’s free HIPAA readiness analysis include, and what does it not include?

ComplianceStack’s free HIPAA readiness analysis is a categorical, directional first pass based on role, organization type, organization size, and ePHI-scope inputs. It does not collect PHI and does not replace an organization-specific risk analysis or formal audit.

What does the $199 HIPAA Evidence-Ready Readiness Pack contain?

ComplianceStack’s $199 HIPAA Evidence-Ready Readiness Pack contains a gated PDF for verified purchasers with nine prioritized gaps, remediation guidance, and nine representative evidence artifacts, each mapped to 45 CFR Part 164 citations and official eCFR sources.

What do ComplianceStack’s public HIPAA gaps and evidence outputs represent?

ComplianceStack’s public nine-gap summary and nine-row evidence checklist are representative, directional readiness outputs with remediation guidance and 45 CFR citations from official eCFR sources. They are not organization-specific audit findings, a formal attestation, or a substitute for an organization-specific assessment.

What should I expect when I start HIPAA Readiness Pack checkout?

ComplianceStack’s HIPAA Evidence-Ready Readiness Pack checkout is Stripe-secured and server-priced at $199, and no account is required. Starting checkout opens the secure payment flow for the paid pack.